GASP AICF

Search controls and profiles

Search by control ID, name, domain or profile

HRS-008 Remote Working Security

Tier 2+ProviderDeployerGPAI Model ProviderManaged Service Provider

Description

Personnel working remotely have documented security requirements covering device security, network access, handling of organisational information outside the office, and reporting of security incidents. Remote workers acknowledge these requirements and receive relevant guidance.

Rationale

Remote working environments cannot be physically controlled by the organisation, creating exposure to eavesdropping, device loss, and use of uncontrolled networks. Defined and communicated controls reduce these risks to an acceptable level.

Applicability (9 profiles)

SaaS AI Providerstablerequiredcore
Enterprise AI Deployerstablerequiredcore
GPAI Model Providerstablerequiredcore
High-Risk Provider (EU)stablerequiredcore
Public Body Deployer (EU)stablerequiredcore
DORA ICT Provider (EU)stablerequiredcore
NIS2 Cloud Provider (EU)stablerequiredcore

Framework Mappings (7)

HRS-04Remote and Home Working Policy and Proceduresfull
HRS-04Remote and Home Working Policy and Proceduresfull
HIPAA-164.310.bWorkstation Useinformative
6.7Remote workingfull
PE-17Alternate Work Sitefull
PS-4Personnel Terminationinformative
CC6.6Security Measures Against Threats Outside System Boundariesinformative

Evidence (2)

policydocumentmanual

Remote working security policy or procedure defining device security, network access, information handling, and incident reporting requirements for remote workers.

Example: Remote Working Security Policy (Confluence / policy management system), covering: approved device types and MDM enrolment requirement, VPN or zero-trust network access requirement, prohibition on use of public Wi-Fi without VPN, handling of paper records at home, and incident reporting for lost devices.

Test: Request the remote working security policy. Verify: (1) device security requirements are specified (e.g. MDM enrolment, full-disk encryption), (2) network access requirements are stated (VPN or equivalent), (3) information handling rules outside the office are included, (4) incident reporting for lost or stolen devices is addressed, (5) the policy is approved and dated within the last 12 months.

recorddocumentmanual

Remote worker acknowledgement records confirming all remote-working personnel have received and accepted the remote working security requirements.

Example: Remote working agreement or acknowledgement records from the HRIS or policy platform (BambooHR / Confluence attestation), showing: employee name, acknowledgement date, and policy version for all employees with a remote or hybrid working arrangement.

Test: Export remote working acknowledgement records. Cross-reference against the list of employees with remote or hybrid working arrangements. Verify: (1) all remote workers have a signed or digitally acknowledged agreement on file, (2) acknowledgement pre-dates or is concurrent with start of remote working, (3) any employees without an acknowledgement have an open remediation action.

Questions (3)

boolean

Does your organisation have documented security requirements for remote working?

The policy should specify MDM enrolment or equivalent device controls, VPN or zero-trust network access requirements, and a process for reporting lost or stolen devices.

select

How are remote working security requirements communicated to and acknowledged by remote workers?

Dedicated remote working agreement signed or digitally acknowledged before remote access is enabledCovered within the general acceptable use policy acknowledgementCovered in security awareness training but not separately acknowledgedRequirements are communicated informally with no formal acknowledgement

All employees with a remote or hybrid arrangement should have a current acknowledgement on file, pre-dating or concurrent with the start of their remote working arrangement.

multi

Which of the following do the remote working requirements cover?

Device security controls, such as enrolment in device managementNetwork access requirementsHandling of organisational information outside the officeReporting of a lost or stolen deviceReporting of security incidentsNone of the above

Options run from the most commonly covered to the least. The lost device route is the one people need at the worst moment and the one most often missing from a policy written around network access.